coupondropdown-bg.exe

CouponDropDown

Awesome Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application coupondropdown-bg.exe, “CouponDropDown exe” by Awesome Apps has been detected as adware by 32 anti-malware scanners. This file is typically installed with the program CouponDropDown by 215 Apps which is a potentially unwanted software program. Part of the Corssrider web browser platform, the BG executable is a background process that manage various function of the installed extensions in user's browser including managing installation, updates and remote code downloads.
Publisher:
215 Apps  (signed by Awesome Apps)

Product:
CouponDropDown

Description:
CouponDropDown exe

Version:
1.1.151.46

MD5:
a935870d1a26a2fc55efb1eeaaf12d74

SHA-1:
03f825d66a74963bd2c2baa56ed47ae2cf82e063

SHA-256:
06bd8a23c9797cc44e7002e96150672f8a35e813a1c4df7d86e8c5ca2f4e37a8

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Awesome Apps.

Analysis date:
4/27/2024 12:24:05 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NNP
367

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

AhnLab V3 Security
PUP/Win32.MulDrop
2014.02.15

Avira AntiVirus
ADWARE/CrossRider.Gen2
8.3.1.6

avast!
Win32:RadyoosMedia-A [PUP]
2014.9-160203

AVG
Crossrider
2017.0.2845

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.1623

Bitdefender
Adware.Agent.NNP
1.0.20.170

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Agent-2199
0.98/21511

Comodo Security
UnclassifiedMalware
22366

Dr.Web
Trojan.Crossrider1.26368
9.0.1.034

Emsisoft Anti-Malware
Adware.Agent.NNP
8.16.02.03.09

ESET NOD32
Win32/Toolbar.CrossRider.H potentially unwanted (variant)
10.11746

F-Prot
W32/Crossrider.B.gen
v6.4.7.1.166

F-Secure
Adware.Agent.NNP
11.2016-03-02_4

G Data
Adware.Agent.NNP
16.2.25

IKARUS anti.virus
AdWare.Agent
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.204.16151

Malwarebytes
PUP.CrossRider.CDD
v2016.02.03.09

McAfee
RDN/Generic PUP.z!fc
5600.6501

MicroWorld eScan
Adware.Agent.NNP
17.0.0.102

NANO AntiVirus
Trojan.Win32.Plugin.crbipj
0.30.24.1636

nProtect
Adware.Agent.NNP
15.06.05.01

Reason Heuristics
PUP.50OnRed.AwesomeApps (M)
16.2.3.9

Sophos
CouponDropDown
4.98

Trend Micro House Call
TROJ_GEN.R0C1C0OLU14
7.2.34

Trend Micro
TROJ_GEN.R0C1C0OLU14
10.465.03

Vba32 AntiVirus
Trojan.Agent
3.12.26.4

VIPRE Antivirus
GamePlayLabs
40904

ViRobot
Trojan.Win32.A.Agent.907648[h]
2014.3.20.0

Zillya! Antivirus
Backdoor.PePatch.Win32.41950
2.0.0.2210

File size:
926.4 KB (948,608 bytes)

Product version:
1.1.151.46

Copyright:
Copyright 2011

Original file name:
CouponDropDown.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\coupondropdown\coupondropdown-bg.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/28/2012 6:00:00 PM

Valid to:
8/29/2013 5:59:59 PM

Subject:
CN=Awesome Apps, O=Awesome Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3D0C9CCF6A7D44B9FDA1963A424319BA

File PE Metadata
Compilation timestamp:
10/25/2012 7:21:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:V426LjFso+pSzEhAWz9w5z46TRkXZGL62kJ:VYjUpSYhAHB4BXZGLjkJ

Entry address:
0x8A405

Entry point:
E8, F4, AC, 00, 00, E9, 89, FE, FF, FF, 2D, A4, 03, 00, 00, 74, 22, 83, E8, 04, 74, 17, 83, E8, 0D, 74, 0C, 48, 74, 03, 33, C0, C3, B8, 04, 04, 00, 00, C3, B8, 12, 04, 00, 00, C3, B8, 04, 08, 00, 00, C3, B8, 11, 04, 00, 00, C3, 8B, FF, 56, 57, 8B, F0, 68, 01, 01, 00, 00, 33, FF, 8D, 46, 1C, 57, 50, E8, AB, CD, FF, FF, 33, C0, 0F, B7, C8, 8B, C1, 89, 7E, 04, 89, 7E, 08, 89, 7E, 0C, C1, E1, 10, 0B, C1, 8D, 7E, 10, AB, AB, AB, B9, A8, 43, 4E, 00, 83, C4, 0C, 8D, 46, 1C, 2B, CE, BF, 01, 01, 00, 00, 8A, 14, 01...
 
[+]

Entropy:
6.5443

Code size:
775 KB (793,600 bytes)

The file coupondropdown-bg.exe has been discovered within the following program.

CouponDropDown  by 215 Apps
Coupon Drop Down from 215 Apps installs a web browser plugin that displays coupon deals and other advertisements when users visit various online shopping sites.
coupondropdown.com
84% remove it
 
Powered by Should I Remove It?

Remove coupondropdown-bg.exe - Powered by Reason Core Security